
WP Mercurial Security & Risk Analysis
wordpress.org/plugins/wp-mercurialBasic Mercurial functionality from the dashboard. Automatically commit after updating core, plugins, or themes.
Is WP Mercurial Safe to Use in 2026?
Generally Safe
Score 85/100WP Mercurial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-mercurial v1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) with unprotected entry points is a significant strength. The code also adheres to good practices by exclusively using prepared statements for SQL queries and properly escaping all output, and not performing file operations or external HTTP requests. The presence of a nonce check and a capability check indicates an awareness of common security controls. Taint analysis showing zero flows with unsanitized paths further reinforces this positive assessment. The complete lack of recorded CVEs and vulnerability history is also a very positive indicator of the plugin's security over time.
While the static analysis reveals no immediate critical vulnerabilities, the presence of 11 'dangerous functions' (specifically 'system') warrants a closer look. Although these functions are not directly exploited due to the lack of attack surface and the presence of checks, they represent potential vectors if the plugin's architecture were to change or if an attacker could find a way to bypass existing controls. The primary concern, therefore, is the *potential* for misuse of these dangerous functions rather than a directly exploitable vulnerability in the current version. Overall, wp-mercurial v1.1 appears to be a securely developed plugin, with the sole area for caution being the use of potentially risky system functions, which are currently mitigated by the plugin's design.
Key Concerns
- Presence of 'system' dangerous functions
WP Mercurial Security Vulnerabilities
WP Mercurial Release Timeline
WP Mercurial Code Analysis
Dangerous Functions Found
WP Mercurial Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Mercurial Maintenance & Trust
Maintenance Signals
Community Trust
WP Mercurial Alternatives
No alternatives data available yet.
WP Mercurial Developer Profile
8 plugins · 76K total installs
How We Detect WP Mercurial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mercurial/wp-mercurial.csswp-mercurial/wp-mercurial.css?ver=HTML / DOM Fingerprints
wp-mercurialid="wp-mercurial"name="wp-mercurial"